SURVEILLANCE / FACE / ILLINOIS

Illinois ID photos & facial recognition

Illinois law requires the Secretary of State to maintain photographs collected through driver's licenses, permits, and identification cards.[1] State law also expressly addresses government requests for facial recognition search services.[1][2]

What this page does not claim: the statutes alone do not tell us how long historical photographs are retained, whether persistent biometric templates or embeddings are separately stored, which agencies actually submit searches, or how often searches occur.

The bottom line

Documented 625 ILCS 5/6-110.1(a)

Illinois maintains a file of photographs collected during licensing and identification.

The Illinois Vehicle Code says the Secretary of State shall maintain, or contract to maintain, a file containing photographs and signatures obtained while issuing driver's licenses, permits, or identification cards.[1]

Documented 625 ILCS 5/6-110.1(b) · 15 ILCS 335/11(f)

Illinois statutes expressly contemplate facial-recognition search services for government requests.

Both the Vehicle Code and the Illinois Identification Card Act contain restrictions on providing facial-recognition search services for federal immigration enforcement.[1][2] The statutory exception language also refers to requests involving criminal activity other than immigration-law violations.[1][2]

Documented 625 ILCS 5/6-110.1(a)(3)

Stored photographs may be disclosed to law enforcement for civil or criminal investigations, subject to statutory restrictions.

The Vehicle Code lists law-enforcement officials conducting civil or criminal law-enforcement investigations among the parties to whom otherwise-confidential photographs and signatures may be disclosed, with additional restrictions elsewhere in the Code.[1]

What the law establishes

The key distinction is between what the statutes literally establish and what would require operational records from the Secretary of State or requesting agencies.

Finding
Status
Primary authority
Photographs and signatures collected during driver's-license, permit, and identification-card issuance are maintained in a file or contracted filing system.[1]
Documented
The Vehicle Code expressly uses the term “facial recognition search services.”[1]
Documented
The Illinois Identification Card Act separately addresses facial-recognition search services and photographs obtained while issuing identification cards.[2]
Documented
The statutes restrict use for federal immigration-law enforcement, while preserving exceptions described in the statutory text.[1][2]
Documented

AGE SCOPE

This is not an adults-only records system

Documented

Illinois state ID cards have no minimum age.

The Illinois Secretary of State states that there is no minimum age for a state identification card.[4] The Identification Card Act allows any Illinois resident who is a natural person to apply, requires the card to include a photograph, and generally requires the applicant to be photographed unless an authorized exception applies.[3]

Illinois law separately provides for instruction permits for minors; the Vehicle Code allows certain instruction permits beginning at age 15.[5]

What this establishes: the photographs collected by Illinois credentialing systems are not limited to adults, and the Identification Card Act's facial-recognition provision applies to photographs obtained while issuing identification cards.[2][3][4]

What this does not establish: these sources do not prove that every minor's photograph is enrolled in a separately stored biometric template, nor do they establish how minor records are technically handled by the facial-recognition system.

Statutory text

The primary statutory text is linked below alongside concise summaries.

PRIMARY SOURCE

625 ILCS 5/6-110.1 — Illinois Vehicle Code

Open on ILGA.gov →

Section 6-110.1 is titled Confidentiality of captured photographs or images. Subsection (a) requires the Secretary of State to maintain a file of photographs and signatures obtained during issuance. Subsection (b) expressly discusses “facial recognition search services” and government requests.

Summary only. Follow the primary-source link for the complete statutory language and all exceptions.

PRIMARY SOURCE

15 ILCS 335/11 — Illinois Identification Card Act

Open on ILGA.gov →

Section 11 governs records associated with Illinois identification cards. Subsection (f) separately addresses facial-recognition search services and photographs obtained in the process of issuing an identification card.

The Identification Card Act separately governs state-ID records and facial-recognition search services.

FAP · FREQUENTLY ARGUED POINTS

Arguments for and against facial recognition

Facial recognition can have legitimate investigative value. The dispute is over when that value justifies making large populations searchable, which safeguards meaningfully constrain use, and who bears the consequences when those safeguards fail.

How to read this section: an argument labeled “for” is not an endorsement, and an argument labeled “against” is not proof by itself. Where the evidence supports both a benefit and a risk, both are stated. Illinois-specific claims remain separate from broader evidence about facial-recognition technology.

Usefulness and necessity

FAP Why shouldn't police use facial recognition to identify a murderer? Argument for

The case for it

This is one of the strongest cases for facial recognition. When investigators possess an image of an unknown suspect in a serious crime, a one-to-many search can produce leads much faster than manually comparing photographs. Federal agencies describe facial recognition as a lead-generating tool, and GAO has found that forensic algorithms can improve speed and objectivity in investigations.[9][13]

A categorical ban can therefore carry a real cost: some violent crimes, missing-person cases, or unidentified-person investigations may take longer to solve, or remain unsolved, when a useful comparison tool is unavailable.

The privacy objection

A compelling use does not answer what the searchable gallery should contain. Searching a narrowly defined collection of photographs connected to criminal justice is a different policy choice from making a general population of licensed drivers and state-ID holders searchable. The seriousness of one investigation can justify the search without automatically justifying the size, permanence, or secondary uses of the underlying database.

NoRec position: the difficult question is not whether facial recognition can ever help solve a serious crime. It can. The question is what population-scale infrastructure society should maintain so that such a search is possible.

FAP If it saves investigators time, isn't that enough reason to use it? Competing considerations

The case for it

Efficiency matters. Investigative resources are finite. A system that turns hours or days of manual comparison into a candidate list can free investigators to pursue corroborating evidence and other cases. GAO has recognized speed and objectivity as potential benefits of forensic algorithms.[9]

The counterargument

Efficiency is not normally the only test for government power. Automation can turn something theoretically possible but labor-intensive into something routine. The policy question is whether the gain in efficiency is proportionate to the additional collection, access, and search capability.

FAP What about missing people, unidentified victims, or someone who cannot identify themselves? Argument for

These are legitimate public-safety and humanitarian uses. Facial comparison may help identify an unknown deceased person, locate a missing person, or establish an identity when ordinary documents are unavailable. Federal descriptions of facial-recognition services include missing and wanted persons among supported uses.[13]

The privacy response is not that these purposes are fictitious. It is that a beneficial purpose should be defined in policy and law rather than used as a blanket justification for unrelated searches.

FAP Can facial recognition help clear an innocent person? Argument for

Potentially. A reliable comparison can point investigators away from an incorrect suspect or toward evidence inconsistent with an accusation. DOJ guidance emphasizes that results require human review and corroboration.[12]

That benefit cuts both ways: if a system can redirect an investigation correctly, a false candidate can redirect it incorrectly. The evidentiary value depends on the algorithm, image quality, threshold, gallery, examiner, and independent corroboration.

Accuracy, bias, and human review

FAP What if facial recognition becomes nearly perfectly accurate? Competing considerations

The argument for broader use

Accuracy is not static. Modern algorithms vary enormously in performance, and the best systems can perform far better than older ones under controlled conditions. NIST continuously evaluates current systems and shows substantial differences among algorithms.[8]

What accuracy does not resolve

Accuracy answers whether the system identifies people correctly. It does not answer whether those people should be identified, which databases should be searchable, how long data should exist, which agencies should have access, or what purposes justify a search.

A perfectly accurate system would eliminate one important objection—misidentification—while making another question sharper: how much identification power should the state possess?

FAP Is the demographic-bias argument outdated? Competing considerations

It should be stated carefully. NIST does not support the blanket claim that every facial-recognition algorithm performs poorly on the same demographic groups. Performance varies by algorithm, application, image quality, age, sex, and demographic group; some high-performing algorithms show much smaller differentials than others.[8]

At the same time, demographic differentials have not simply vanished. NIST's current evaluation continues to measure differences in false-positive and false-negative rates across demographic groups.[8] That makes procurement, testing, thresholds, image quality, and the consequences of a false candidate relevant to responsible deployment.

NoRec position: privacy objections should not depend on exaggerating algorithmic bias. If disparities improve, that is good. Population-scale biometric search still raises separate questions.

FAP Does a trained human reviewing every result solve the problem? Competing considerations

Human review is an important safeguard. The FBI says its facial-recognition results are investigative leads rather than positive identifications and describes trained examiner review and additional investigation before action.[13] DOJ has likewise recommended trained human review, thresholds, corroboration, and safeguards against automation and confirmation bias.[12]

But human review is not infallible. A reviewer can be influenced by a ranked candidate list, similarity score, case knowledge, or confirmation bias. Human review also does not resolve collection, retention, access, permissible-purpose, or gallery-scope questions.

FAP If a match is only an investigative lead, why worry? Competing considerations

Calling a result a lead is a meaningful safeguard when agencies actually enforce that distinction. FBI policy says candidate photos are not positive identification and should not be the sole basis for law-enforcement action.[13]

A lead can nevertheless affect a real person: who receives scrutiny, whose alibi is examined, who is interviewed, and which evidence investigators seek. DOJ recommends that facial-recognition results not establish probable cause or positive identification without corroboration.[12]

Privacy, consent, and public space

FAP If I'm not doing anything illegal, why should I care? Argument against

Because privacy protects lawful life as well as unlawful conduct. Movements, associations, political activity, religious attendance, medical visits, relationships, and daily routines can be sensitive without being criminal.

The strongest opposing argument is that government already possesses identifying records for legitimate administrative purposes and that a person in public generally cannot expect to be unseen. Facial recognition can also help investigate crimes that harm other people's rights.

The response is one of scale. Being observable by people nearby is not identical to being cheaply searchable across large image collections. GAO has identified loss of anonymity and the ability to identify or track people in public as recurring privacy concerns.[10]

FAP If my face is visible in public, how can recognizing it be a privacy issue? Competing considerations

The argument for use is straightforward: faces are ordinarily exposed in public, and people have always been capable of recognizing one another. Facial recognition automates an observation humans can already make.

The counterargument is that automation changes practical anonymity. A stranger may see your face without knowing your name. A networked system can connect an otherwise anonymous face to an identity at machine speed and repeat that process at scale. GAO has described concerns that widespread facial recognition could enable identification and tracking in public without knowledge or consent.[10]

FAP The state already has my driver's-license photo. What's different about searching it? Competing considerations

There is a legitimate administrative reason for the state to possess a driver's-license or ID photograph: issuing and controlling an identity credential. Illinois law requires the Secretary of State to maintain captured photographs.[1]

The privacy distinction is secondary use. A photograph collected to issue a credential can also become part of an identification infrastructure useful to agencies pursuing unrelated investigations. Illinois itself treats the images as confidential and specifies who may receive them.[1]

Illinois law and the scope of access

FAP Does “criminal activity” mean Illinois facial-recognition searches are criminal-investigations-only? Statutory interpretation

Not clearly. In 625 ILCS 5/6-110.1(b), the phrase appears in an exception to a prohibition concerning federal immigration-law enforcement. Read in context, it says that the subsection's immigration restriction does not apply to requests relating to other criminal activity.[1]

Elsewhere, subsection (a)(3) permits disclosure of captured photographs for a “civil or criminal law enforcement investigation.”[1] Illinois Administrative Code §1030.140 likewise identifies Illinois, federal, and out-of-state criminal-justice agencies as authorized recipients of images for lawful civil or criminal law-enforcement investigations.[7]

What remains unresolved: those provisions clearly address access to captured images, while subsection (b) specifically names facial-recognition search services. The cited text does not cleanly answer whether every civil investigation eligible to receive an image is also eligible for a facial-recognition search. NoRec therefore does not label civil facial-recognition searches as established fact.

FAP Doesn't Illinois prohibit using these systems for immigration enforcement? Statutory interpretation

Illinois law does contain a meaningful restriction. The Vehicle Code and Identification Card Act prohibit the Secretary of State from providing specified facial-recognition search services or photographs when the purpose is enforcement of federal immigration laws, subject to the statutory language concerning other criminal activity.[1][2]

That protection should be acknowledged rather than ignored. It does not answer retention, technical architecture, search volume, requesting agencies, non-immigration uses, or practical auditing.

FAP If Illinois calls the photographs confidential, doesn't that protect them? Competing considerations

Confidentiality is a real protection. Illinois statutes and administrative rules limit disclosure, identify eligible recipients, constrain secondary dissemination, and require secure handling in specified circumstances.[1][7]

“Confidential” does not mean “never accessed.” The same rules enumerate government and criminal-justice uses. The privacy question is the breadth of authorized access and whether the controls are sufficient.

FAP Why emphasize minors if state IDs can legitimately be issued to children? Competing considerations

The fact that minors can receive state IDs is not itself evidence of wrongdoing. Children may need identification for ordinary reasons. Illinois says there is no minimum age for a state ID card.[4]

The relevance is scope. If the public assumes a driver's-license/ID photo system represents only adult motorists, that assumption is incorrect. The credential population can include minors. That matters when evaluating retention, secondary access, and facial-recognition capability associated with those records.

Security, sharing, and commercialization

FAP What if I trust the government and its employees? Argument against

Then the argument shifts from intent to security. A system can be compromised without an authorized employee deliberately abusing it. Credentials are phished, software contains vulnerabilities, cloud systems are misconfigured, contractors are breached, and trusted accounts can be hijacked.

GAO has identified data-security risks for facial-image datasets and noted that biometric information has a different consequence from a password because a person's face is effectively permanent and cannot simply be replaced after exposure.[10]

Trust in an agency therefore does not eliminate the case for data minimization, retention limits, access controls, auditing, and incident planning.

FAP Why shouldn't agencies share the data if another agency has a legitimate case? Competing considerations

Sharing can prevent duplication and help investigate a case when a useful record is held elsewhere. Illinois administrative rules contemplate dissemination to eligible criminal-justice agencies and impose conditions on secondary dissemination.[7]

But every additional recipient creates another place where policy, credentials, logging, retention, and security must work. GAO found federal agencies had used non-federal facial-recognition systems without adequate mechanisms to track employee use, creating privacy and risk-assessment problems.[11]

FAP What's wrong with a private company providing the technology? Competing considerations

Nothing about private development automatically makes a system illegitimate. Specialized vendors can build technology that would be expensive for each agency to develop independently, compete on accuracy and cost, and maintain infrastructure.

The concern is incentive and control. A vendor may benefit from expanding customers, searchable data, integrations, or capabilities. Government users can become dependent on systems partly outside public institutions. GAO has documented federal use of non-federal, including commercial, facial-recognition systems and called for improved tracking and risk assessment.[11]

NoRec position: commercialization is not proof of abuse. It is a reason to ask who owns the infrastructure, who can access the data, what happens when a contract ends, what incentives favor expansion, and which records remain subject to public oversight.

FAP Is a biometric breach really worse than any other data breach? Argument against

Not in every consequence, but biometrics have a distinctive revocation problem. A stolen password can be reset. A compromised key can be rotated. A person's face cannot be replaced in the same way.

That does not mean a stolen facial template automatically lets an attacker impersonate someone in every biometric system; implementations and templates differ. The narrower claim is that exposure of facial images or derived biometric data can create long-lived risk because the underlying physical characteristic is persistent. GAO has explicitly identified this concern.[10]

Oversight and the actual disagreement

FAP Would warrants, audits, retention limits, and strict policies solve NoRec's objection? Competing considerations

They would solve or reduce several objections. A strong legal predicate can narrow when a search occurs. Audit logs can make misuse detectable. Retention limits reduce historical exposure. Independent review can test compliance. Public policies make rules contestable. Training and corroboration reduce the risk of treating a candidate as an identification.[12]

Those are meaningful safeguards, not theater.

NoRec's remaining objection is structural: even a well-governed population-scale biometric system creates an identification capability that would not otherwise exist. NoRec favors the narrowest collection and search authority compatible with a demonstrated need. Someone can reasonably conclude that strict safeguards make a particular use acceptable; NoRec can acknowledge that argument while still preferring less surveillance infrastructure.

FAP Is NoRec arguing that all facial recognition should be banned? Competing considerations

NoRec's position on this page is narrower: population-scale government biometric search deserves a presumption against expansion and a high burden of justification. Device authentication, one-to-one verification, forensic one-to-many searching, real-time identification, and persistent tracking are materially different applications.

A person can oppose real-time mass identification while accepting a warrant-based forensic search for a violent felony. Another person can reject both. The FAP exists so those distinctions remain visible instead of collapsing the debate into “facial recognition good” versus “facial recognition bad.”

FAP So what is NoRec actually arguing for? Argument against

Evidence before rhetoric. Narrow purposes instead of open-ended authority. Data minimization instead of collection because storage is cheap. Defined retention instead of “keep it in case it becomes useful.” Search predicates that can be audited. Independent corroboration before action. Public rules for government systems. Meaningful restrictions on secondary dissemination. Procurement records and vendor relationships that can withstand scrutiny.

And, where a surveillance capability is not necessary or proportionate to a demonstrated need, do not build it merely because technology makes it possible.

What the statutes do not establish

A reference to facial-recognition search services is evidence that the capability is contemplated in law. It is not, by itself, evidence of every technical or operational detail of the system.

Unknown

How long are historical photographs retained?

The statutes reviewed for this page require photographs to be maintained but do not, in the cited sections, establish a retention period for older or superseded photographs.

Unknown

Are persistent facial templates or embeddings separately stored?

The statutes use the term “facial recognition search services,” but that wording does not establish the system's technical architecture or whether a separately retained biometric representation exists for each person.

Unknown

Which agencies actually submit searches?

The law describes categories of governmental requesters. It does not identify, in these sections, the agencies that have actually used the service.

Unknown

How many searches occur?

Nothing in the cited statutory text establishes search volume, frequency, hit rate, rejection rate, or the number of people whose images have been queried.

Unknown

How often do federal or out-of-state agencies use the service?

The statutory language refers broadly to federal, State, and local law-enforcement agencies and other governmental entities, but operational usage requires separate evidence.

Under investigation

Under investigation

Operational details not established

The available record does not establish complete retention schedules, operational facial-recognition policies, audit activity, aggregate search counts, requesting-agency activity, system architecture, or how photographs are prepared for and submitted to facial-recognition systems.

Questions not resolved by the available record remain labeled UNKNOWN.

Research & FOIA docket →

LEGISLATIVE CONTEXT · NOT CURRENT LAW

A 2026 proposal would go substantially further

House Bill 5521, introduced in the 104th General Assembly, proposes an Illinois Biometric Surveillance Act and would sharply restrict law-enforcement use of biometric identification systems. As of this page's September 9, 2026 review, the General Assembly lists the bill's last action as re-referral to the House Rules Committee on March 27, 2026.[6]

HB5521 is a proposal, not evidence that its proposed restrictions are currently law.

View HB5521 on ILGA.gov →

Primary sources

  1. [1] · IL-LAW-001
    625 ILCS 5/6-110.1
    Illinois Vehicle Code — Confidentiality of captured photographs or images
    Illinois General Assembly
  2. [2] · IL-LAW-002
    15 ILCS 335/11
    Illinois Identification Card Act — Records
    Illinois General Assembly
  3. [3] · IL-LAW-003
    15 ILCS 335/4 and 15 ILCS 335/5
    Illinois Identification Card Act — eligibility, card photograph, and application requirements
    Section 4 on Illinois General Assembly · Section 5 on Illinois General Assembly
  4. [4] · IL-SOS-001
    Driver’s License and State ID Card Information
    Illinois Secretary of State — states that there is no minimum age for a state ID card
    Illinois Secretary of State
  5. [5] · IL-LAW-004
    625 ILCS 5/6-103 and 625 ILCS 5/6-107.1
    Illinois Vehicle Code — instruction permits for minors, including certain permits beginning at age 15
    Section 6-103 on Illinois General Assembly · Section 6-107.1 on Illinois General Assembly
  6. [6] · IL-BILL-001
    HB5521 — Biometric Surveillance Act
    104th General Assembly — legislative context only
    Illinois General Assembly
  7. [7] · IL-RULE-001
    92 Ill. Adm. Code 1030.140 — Use of Captured Images
    Illinois Secretary of State rules governing access, recipient retention, secondary dissemination, and civil or criminal law-enforcement investigations
    Illinois General Assembly / JCAR
  8. [8] · US-NIST-001
    Face Recognition Technology Evaluation — Demographic Effects
    National Institute of Standards and Technology — ongoing measurements of demographic differentials
    NIST
  9. [9] · US-GAO-001
    GAO-24-107206 — Forensic Technology
    Benefits and limitations of forensic algorithms in criminal investigations
    U.S. GAO
  10. [10] · US-GAO-002
    GAO-20-522 — Facial Recognition Technology
    Privacy, security, permanence, consent, and accuracy issues involving facial-image datasets
    U.S. GAO
  11. [11] · US-GAO-003
    GAO-21-518 and GAO-22-106100 — Federal use of facial recognition
    Non-federal systems, tracking deficiencies, and privacy-risk assessment
    GAO-21-518 · GAO-22-106100
  12. [12] · US-DOJ-001
    Artificial Intelligence and Criminal Justice — Final Report
    DOJ recommendations on thresholds, human review, bias, corroboration, and investigative leads
    U.S. Department of Justice
  13. [13] · US-FBI-001
    Law Enforcement’s Use of Facial Recognition Technology
    FBI description of FACE Services, candidate review, investigative-lead use, and state/federal repositories
    FBI

METHODOLOGY

Corrections and methodology

The project is explicitly pro-privacy. Factual claims are still limited to what the cited evidence supports, and errors should be corrected.

Read about the project →